Google Patches a Pixel Modem Flaw It Says May Already Be in Use

Google published its Pixel Update Bulletin for September 2026 on Sept. 15, fixing security flaws in supported Pixel phones. A note at the top singles out one of them. "There are indications that CVE-2026-58704 may be under limited, targeted exploitation," the bulletin says.
That sentence is the whole of what the bulletin says about exploitation. The fix has already shipped. Security patch levels of 2026-09-05 or later address every issue in the bulletin and every issue in the September 2026 Android Security Bulletin, Google says, and the page links its own instructions for checking which level a phone is on.
The bulletin's table lists the flaw against the Modem component and rates it High. It classifies the bug as elevation of privilege, meaning software on the device gains permissions it was not granted.
